LightSC: The Making of a Usable Security Classification Tool for DevSecOps
Manish Shrestha, Christian Johansen, Johanna Johansen

TL;DR
This paper presents LightSC, a usability-focused security classification tool designed for DevSecOps, emphasizing ease of use for non-security experts and integrating into rapid development cycles.
Contribution
It introduces principles for creating DevOps-ready security classification methods and provides a practical, user-centered approach to develop and evaluate such tools.
Findings
The tool is most useful during the design phase.
It supports security classification as a metric in testing.
A general three-step recipe for making security methods DevOps-ready.
Abstract
DevSecOps, as the extension of DevOps with security training and tools, has become a popular way of developing modern software, especially in the Internet of Things arena, due to its focus on rapid development, with short release cycles, involving the user/client very closely. Security classification methods, on the other hand, are heavy and slow processes that require high expertise in security, the same as in other similar areas such as risk analysis or certification. As such, security classification methods are hardly compatible with the DevSecOps culture, which to the contrary, has moved away from the traditional style of penetration testing done only when the software product is in the final stages or already deployed. In this work, we first propose five principles for a security classification to be \emph{DevOps-ready}, two of which will be the focus for the rest of the paper,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsScientific Computing and Data Management · Big Data and Business Intelligence
